๐Ÿ” CVE Alert

CVE-2026-78428

HIGH 8.0

Flaw in Nuevector can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

CVSS Score
8.0
EPSS Score
0.0%
EPSS Percentile
0th

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

Vendor go
Product neuvector
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for go neuvector

Be the first to know when new high vulnerabilities affecting go neuvector are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

go / neuvector
<5.6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/neuvector/neuvector/security/advisories/GHSA-c6rx-pmvf-m3jx bugzilla.suse.com: https://bugzilla.suse.com/show_bug.cgi?id=1279937